Security researcher found bugs in Google's bug tracker

Image
IANS San Francisco
Last Updated : Nov 01 2017 | 10:22 AM IST

A security researcher has discovered bugs in Google's platform that deals with bugs and unpatched vulnerabilities, leading him to gain access to the company's sensitive internal systems.

According to a report in Motherboard in Wednesday, Alex Birsan found vulnerabilities inside the Google Issue Tracker - used internally to track bugs and feature requests during product development.

The largest one of these was one that allowed the researcher to access the internal platform at all. The company has quickly patched the bugs found by Birsan and there's no evidence anyone else found the bugs and exploited them, the report added.

Birsan found three bugs in the platform.

"Exploiting this bug gives you access to every vulnerability report anyone sends to Google until they catch on to the fact that you're spying on them," Birsan told Motherboard.

"They are all patched now and he received rewards of $3,133.7, $5,000, and $7,500 for reporting them to Google," the report said.

Issue Tracker is available outside of Google for use by external public and partner users who need to collaborate with Google teams on specific projects.

The platform has access control permissions that govern which users can find, view, create and modify issues for each project.

"We appreciate Alex's report. We've patched the vulnerabilities that he reported, as well as their variants," a Google spokesperson was quoted as saying.

--IANS

na/amit

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Nov 01 2017 | 10:06 AM IST

Next Story